First published: Mon Jul 20 2020(Updated: )
OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Openclinic Ga Project Openclinic Ga | =5.09.02 | |
Openclinic Ga Project Openclinic Ga | =5.89.05b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14494 is a vulnerability found in OpenClinic GA versions 5.09.02 and 5.89.05b that allows unauthorized users to access the system through brute force attacks.
CVE-2020-14494 has a severity rating of 9.8, which is considered critical.
OpenClinic GA versions 5.09.02 and 5.89.05b are affected by CVE-2020-14494.
CVE-2020-14494 impacts the OpenClinic GA authentication mechanism by not providing sufficient complexity to protect against brute force attacks.
A fix for CVE-2020-14494 is not explicitly mentioned in the provided information, but it is recommended to update to a secure version of OpenClinic GA if available.